HNHacker News
TopNewBestAskShowJobs

a904guy

530 karma · joined August 11, 2010

Andy Hawkins

destructive criticism need not apply

http://a904guy.com/

                         S.;@88888X%..%8                     
                    X:t%@8888@XS%t;. .:tSX88S                
                 %.tX888888@S%t;:. .;;%%X@8888S%             
              @.;X8@8888@XStt;...:;t%SX@8888888%.;           
            %.t88@888@@SStt;. .;tSX@88888888@@XS%:t8S        
          S.%8@8888@XSS%t;.S@        X8S;;ttS%t;:. ;88:      
         .t8@8888@XXSS:                    .S%:. .:ttSt      
       ;t@8888@@SXSt                         :88%t%SX@@ t    
      .S8888@XSSSt                              S%S88888t8   
     %@88@@X%%%tS           888XSS                 @8888S88  
    S888XSSt;;.         @88@@@X%t:.%@% t88@X%t; : X%@88@X.@  
   ;88XS%t;:.:        8888888XX%t;:.:@88X%XX888;8  8XXXS%t:; 
   8@St;:. .%       8@888@@XS%t;:  ::;%SS@8888%@    8.%;:. : 
  %@t;:. .;%       @X888XXSt;:. .:;t%SX@888@88%8    S;:. .:%.
  St:  :;tS       SS8@@S%t;: %X@XS%S@8888@888X8@    %. :;t%X@
 %; .:;t%88      ;t@XS%t;. @8S    S .8888888@ @     S;.t%SXS8
 ..:ttSX@8X     ; %St;:. ;8@        %%8888@S%t%     tX:X@88:@
 ;%%SX@888      ; t;:. .t8S          8.@XS%t.:%     %8%8888.t
 X@@88888S     ;S:...:;tSS           8;%%;:...      8@88888.:
 8888888X.     S@ .:;t%S;.           @.;:. :;%     .8S8888X. 
 888888@%:;    88;;%SX@@ ;          St. .:;:Xt     @.888@St% 
 8%@88XStS%    @8%SX@888.S         %: .:;t%.8     ;;X@XSt%X  
  .tS%t;:S8    :%X@888888t8      8: ::ttSX@:8    .:SS%t;%88  
  .;t;:..;8.    .;8888888@ SXSt:. .;t%SX888%@. ;..%%t;:t8@   
   @; .:;tSS     t:8888@S%t;:...:tt%X@::8888%::;%%;;..%8@    
   @8:;t%XX;.     8tXXS%t;:...;t%SX@X;88%88@@SSt;:. ;88      
    8XSX@888.%     8X ;:. .:;t%SX@%:@S :;:SS%t;: :%@88       
     tt8888@8%8      %: . ..:: ;%8@      Xt%XX@8888          
      ..88888@;88       t tSXXt:                             
       XtX8@SSt:;:%                                          
        88 %t;:. . ttt                         @tS           
          X:.  :;t%%:t88S.             S@8X%; ;S%%           
           S...t%XX88888S;:..:;tSSX@@St:.;%@888888           
             .XS @8888888@SSt;;. .:;t%S@@8888888888          
                @8;t@8@@S%t;:. ::ttSX@8888888888@88          
                   ;. ;t%%t:..:;%%SX@@8888888888%.S          
                        @8@@88X%t: .;.;...:

YW5keUBhOTA0Z3V5LmNvbQ==

[ my public key: https://keybase.io/a904guy; my proof: https://keybase.io/a904guy/sigs/B_EBJ3huUPfFzzPnMTBF9GHCw4zac9O4GzbcfCjvZV8 ]

submissionscomments
a904guy··on The beauty of a text only webpage
I wasn't. I indeed find the site to be fun, and fits the author's own words.

> “So thank you to everybody who writes and publishes text-only webpages.”

The site is 100% text.

a904guy··on The beauty of a text only webpage
Guilty on the splash. Regardless the entire site is clean text, fast loads, no images, and no blockers.

In the author's own words:

> “So thank you to everybody who writes and publishes text-only webpages.”

a904guy
·
·on The beauty of a text only webpage
Ooo, I have a fun one!

https://hawkins.tech/

a904guy··on Smart Segments: Krita plugin that adds Segment Anything V2 object selection
I built a Krita plugin called Smart Segments that lets you easily select objects using Meta’s Segment Anything Model (SAM v2). Just run the tool, and it automatically finds everything on the current layer. You can click or shift-click to choose one or more segments, and it converts them into a selection. No more struggling with the magic wand or cutting stuff out by hand. It supports GPU and CPU, works on Windows, macOS, and Linux, and sets everything up on first run without needing to install anything manually.
a904guy··on Show HN: CryptoCurrencies Market, Poloniex. Supports Streaming, and REST API
No, not at the moment. Just need an account.
a904guy··on Show HN: Liveform. Creating an Imgur Clone Using GitHub Pages and Liveform
Didn't really take your own advice in keeping your API key safe :)
a904guy··on Nootrobox Launches Smart Drugs Subscription Service
The ingredients can be purchased on Amazon (Prime too)

http://www.amazon.com/Nutrigold-Bacopa-Clinically-proven-Bac... http://www.amazon.com/Now-Foods-L-Theanine-Veg-Capsules-60-C...

a904guy··on SQL Injection Galore
Django... https://github.com/search?q=extension%3Apy+os.system+%22requ...
a904guy··on SQL Injection Galore
CGI Python? Happens... https://github.com/search?q=extension%3Apy+os.system+%22impo...
a904guy··on SQL Injection Galore
I always preferred the remote code execution search myself personally...

https://github.com/search?q=extension%3Aphp+exec+%24_GET&typ...

a904guy··on ArXiv vs snarXiv
Oops: Was going for the high score...

OperationalError: (1203, "User #### already has more than 'max_user_connections' active connections")

a904guy··on ArXiv vs snarXiv
Nobel Prize Winner ( aka Ed ) goes to:

$("a:contains("+arxiv['title']+")").click();

a904guy··on Show HN: My HTML5 Game for Github Game Off
mit.score = 1337000000001337;
a904guy··on Bootstrap Toggle Buttons
#1: Not really impossible, just requires additional maintaining of a monitor, methods within the script, or custom triggers to handle the switch.
a904guy··on Bootstrap Toggle Buttons
Looks great.

Two things,

#1: If you modify the attribute checked of the input, the state doesn't change.

#2: I don't see a programmatic way of changing the state from your source without re-initializing all the elements?

a904guy··on Why Is The Defense Department Snooping On My Phone?
A (extremely) large number of usual local network IP ranges are issued to the DOD. Including my local subnet as well. 11.1.11.0/24, if I ran a whois on that IP as well, it would return DOD, but that doesn't mean the DOD is snooping my network, it just means my router has all the routes for 11.1.11.0/24 associated with it and doesn't actually attempt to send traffic over the wire to that IP. I assume your Android phone is listening locally on that address for the VOIP communication, which would in return mean the DOD is NOT snooping on your phone. Much similar to apache or (insert other socket application) listening to 127.0.0.1:80 for local only traffic.
a904guy··on Introducing MotionCAPTCHA: Stop Spam, Draw Shapes
As far as I can tell from the demo there is no server side validation on this captcha. Everything is handled on the client side. So really all your doing is making an annoyance for your honest target users. And allowing a spam bot to just totally ignore this 'captcha' to submit their POST regardless....

I've seen hundreds of these 'alternative' captchas. 'slide to unlock', 'sort images' ect. None yet have proven to be as effective at stopping a simple curl script.

Real captchas will store the value of the image or verification method on the first fetch in a session, and when the form is finally filled out the server will verify that the session value matches the submitted value. Without this component, the alternative captchas are pointless and just an annoyance to your real users.

Spam bots are not built on top of web browsers...

a904guy··on SSH Key Gen/Install Script. Automates Mass Distribution of SSH Keys
Ahh! good catch, Thank you. I'll zdd that in tomorrow.
a904guy··on SSH Key Gen/Install Script. Automates Mass Distribution of SSH Keys
... well. Since we are going deep down the rabbit hole. So your machines other users are potentially a threat. Considering that the folder and contents are chmod 600. Only the owning user and root can see them. The key pass is pointless without the key files.

While we are on the subject. Lets dig deeper on this situation. Whats stopping your rouge user on the same box (that can dump the proc table while ssh-keygen is executing in ms) from dumping the ram to extract the stdin password typed out by keyboard then?

If you already have fear of a user INSIDE your box. SSH keys should be the least of your concerns.

a904guy··on SSH Key Gen/Install Script. Automates Mass Distribution of SSH Keys
For the ability to remove a key from a single device/server. Considering the keys are tagged with user+host, removal is easily identifiable. A single key solution isn't ideal for my configuration.

Using ssh-copy-id is the standard method, but doesn't suite what I wanted.

a904guy··on SSH Key Gen/Install Script. Automates Mass Distribution of SSH Keys
When you run ssh-keygen it creates the two keys, public and private, neither contain the 'plaintext' passphrase in your home directory like you mentioned. The only concern may be bash history, I'll include a wipe for that. Secondly, even while being transmitted using SSH they are NOT in plain-text. As the SSH connection itself is encrypted, so while executed in plaintext, the password is NOT stored in plain text, or transmitted in plaintext as identified by those commands.

Finally, the remote_password being blank is by design, passwordless keys are less of a security threat than any weak user supplied password. They serve their purpose in the real world amongst private networks.

EDIT for 'and in the command line.': Reviewing the command history doesn't show the libssh2 or php5 commands being executed on either BSD or debian.

EDIT for your comment 'in the config file': If your suggesting that the software is insecure by the fact that the user leaves the config file after usage, then perhaps that user should be allowed in the environment to begin with.

a904guy··on SSH Key Gen/Install Script. Automates Mass Distribution of SSH Keys
The language doesn't really matter, especially considering its a single use app. It can be done via any LibSSH2 binding, or even with a more complex expect binding.

The reason for php is simple, I had already wrote the libssh2 code for what I needed. I submitted it, in hopes it saves someone else the time.

a904guy··on SSH Key Gen/Install Script. Automates Mass Distribution of SSH Keys
MediaTemple VPS... Time to migrate to my rackspace server.
a904guy··on SSH Key Gen/Install Script. Automates Mass Distribution of SSH Keys
For your comment that was edited stating: "the script was storing passwords in plain-text in the user home folder", There is no plaintext passphrases stored anywhere... and you can use different passwords per each device per the config file. This script follows the exact procedure for ssh-keys defined by OpenSSHD in general, ssh-keys are more secure than logging in using a password in general. As for the reverse connections, I have a version that utilizes the reverse key in the config array that keeps them from distributing across server, only to and from the localhost. I took it out to roll this version out as I still haven't tested it fully.
a904guy··on Torrent meta-search engine
I love the interface. I give you my up-vote.
a904guy··on Complete Hacker Tutorial to getting Time Machine over NFS to work.
It works out great for me. I work primarily on a Ubuntu Desktop but for my Mac Air, all my files are on other servers, so really I only have locally Xcode and my development tools.

I assume everyones situation is different, I wouldn't be attempting to use TimeCode on a couple TB drives of a MacPro tower.

a904guy··on Complete Hacker Tutorial to getting Time Machine over NFS to work.
I thought the same. I tested EXT4 on a fresh Ubuntu 10.10 system. My variables wouldn't save till I declared it.
a904guy··on Complete Hacker Tutorial to getting Time Machine over NFS to work.
Sarcasm and 14 Karma... original. ;)
a904guy··on Complete Hacker Tutorial to getting Time Machine over NFS to work.
I've already implemented AFP via netatalk. I'll do a write up on the process in a bit.

Personally I don't much care for SMB... but I've implemented it as well for our Windows boxes to backup over.

a904guy··on Complete Hacker Tutorial to getting Time Machine over NFS to work.
The restore works just like any other Time Machine restore. In critical data loss when the machine has to be formatted. You will be able to restore the system completely from the Time Machine. Just remount the NFS on the new OS and run to command so Time Machine will see NFS mounts and click Restore.

~@

Page 1 of 2Next →